← Back to browse · API

CVE-2025-47813

Severity
MEDIUM
CVSS
4.3
EPSS
0.58727
Risk score
62.75
CISA KEV
Yes
PoC
No
Published
2025-07-10
Modified
2026-03-17
First seen
2026-08-07
Aliases
EUVD-2025-21020, GHSA-2VVG-J984-HH8P
Products
Wing FTP Server:Wing FTP Server, Wing FTP Server:Wing FTP Server 0 <7.4.4
Sources
cisa.gov CVE-2025-47813
euvd EUVD-2025-21020

Description

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie.

References